CVE-2026-58222
Red Hat · Red Hat Enterprise Linux
A security flaw in the Samba Active Directory Domain Controller within Red Hat Enterprise Linux allows authenticated users to perform LDAP filter injection and bypass authorization checks.
Executive summary
A critical LDAP injection vulnerability in the Samba Active Directory Domain Controller on Red Hat Enterprise Linux permits authenticated users to escalate privileges and compromise domain data.
Vulnerability
The vulnerability involves improper neutralization of special elements used in LDAP queries, which, when combined with flawed authorization logic, allows an authenticated user to manipulate backend directory queries.
Business impact
Successful exploitation allows an authenticated attacker to gain unauthorized access to sensitive directory information or potentially escalate privileges within the domain. With a CVSS score of 8.8, this vulnerability represents a significant risk to the confidentiality and integrity of the entire identity infrastructure.
Remediation
Immediate Action: Consult the official Red Hat security advisory and apply the relevant patches for the Samba AD DC component across all affected RHEL versions.
Proactive Monitoring: Monitor directory service logs for abnormal LDAP queries or unauthorized attempts to access restricted attributes within the Active Directory environment.
Compensating Controls: Restrict access to administrative domain functions and implement granular permission sets to limit the damage an authenticated user can inflict.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
This vulnerability targets the core identity infrastructure of an organization. Security teams must treat this as a high-priority item and coordinate with Red Hat support to apply the necessary patches as soon as they are released for their specific environment.